Executive brief
Capgo, a platform for managing app updates, contained a security flaw that allowed unauthorized individuals to view sensitive business information. By accessing specific public-facing interfaces, an attacker could verify the existence of specific organizations and identify which ones are paying customers. This information could be used for targeted phishing attacks or competitive intelligence gathering.
Technical details
An information disclosure vulnerability exists in Capgo versions prior to 12.128.2 due to improperly secured Supabase PostgREST RPC endpoints. Specifically, the 'is_trial_org' and 'is_paying_org' endpoints can be invoked by unauthenticated attackers using a public 'sb_publishable' key. The 'is_trial_org' endpoint acts as an existence oracle by returning an integer for valid organizations and 'null' for non-existent ones, while 'is_paying_org' returns a boolean indicating billing status. This allows for large-scale organization enumeration and customer profiling. The issue was resolved in version 12.128.2 by restricting these RPCs to authenticated contexts or ensuring uniform responses.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-03-17: advisory: Initial GitHub security advisory published
- 2026-06-20: disclosed: CVE published to NVD dataset